설명
OpenAPI 2.0의 전역 security 설정에서 해당 OAuth2 방식의 securityDefinitions에 없는 스코프를 참조하면, 문서에 정의된 권한과 요구하는 권한이 서로 맞지 않습니다.
잠재적 영향
API 사용자가 필요한 권한을 잘못 이해하거나 문서 검증과 클라이언트 생성 과정에서 오류가 발생할 수 있습니다.
해결 방법
전역 security에서 참조하는 스코프 이름을 해당 방식의 scopes와 맞추십시오. 오타나 불필요한 스코프는 수정하거나 제거하고, 필요한 권한이 정의에서 빠졌다면 인증 서버의 실제 권한에 맞게 추가하십시오.
예시
예시는 정의되지 않은 error:api를 제거합니다. 실제로 필요한 권한이라면 제거하는 대신 정의를 바로잡아야 합니다.
변경 전
yaml
swagger: "2.0"
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis
security:
- oAuth2AuthCode:
- read:api
- error:api
변경 후
yaml
swagger: "2.0"
securityDefinitions:
oAuth2AuthCode:
type: oauth2
flow: accessCode
authorizationUrl: https://api.example.com/oauth/authorize
tokenUrl: https://api.example.com/oauth/token
scopes:
read:api: read your apis
security:
- oAuth2AuthCode:
- read:api